MEDIUM

CVE-2026-48928

Nodejs Node.js 2026-06-26 CVSS v3.1
CVSS
5.4

Description

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

0.22%
Probability of exploitation in next 30 days
12.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE